Author Topic: Possible Keyloggers  (Read 1339 times)

Offline firefly

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Possible Keyloggers
« Reply #20 on: May 19, 2009, 02:24:50 PM »
excellent, got those updates taken care of.  A free antivirus option would be good.. I don't really know what one to use, I believe this computer came with Mcafee, but was only a trial version.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Possible Keyloggers
« Reply #21 on: May 19, 2009, 02:37:00 PM »
Try this one>Avira AntiVir, give it a chance, if you don't like it, come back and we'll try something else, but I use it on one of my computers, it's very competent
I would like to see a log from it please after you install it, I'll give instructions below:

Go to the following link:
http://download.cnet.com/Avira-AntiVir-Per...cdlPid=11012914
Download and save the installer to desktop>>>Link is Download Now  (28.68MB)


Right click on the Avira installer on desktop and choose to "Run As Administrator"
Ensure that you have it check for Updates
The first time it updates may take awhile, but allow it time

NOTE: Avira will display a single big Ad on your computer
Don't be alarmed, just click OK at the bottom of the Ad to close it

A scan of your System should then start
If a scan does not start after updating, double click on the Avira icon by the clock (the red/white umbrella)
and select "Scan system now"

Quarantine or delete everything it finds
When the scan is finished
Reboot the computer

Back in Windows
Can you post all the following back please

 Please post the log from Avira
Open Avira again (Double click on the red Umbrella icon by the clock)
Click on REPORTS under Overview
Double click on the Scan report you just made
Then click on "Report File"

Edit>>In addition, right click on Hijackthis shortcut on desktop and "Run as Admin"
Run a fresh Scan and Save logfile and post the new log
« Last Edit: May 19, 2009, 02:42:53 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline firefly

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Possible Keyloggers
« Reply #22 on: May 19, 2009, 03:45:19 PM »
That scan took awhile, but it seems like a decent program, I'll give it a try for a bit =)  here's the report:



Avira AntiVir Personal
Report file date: Tuesday, May 19, 2009  12:54

Scanning for 1410306 virus strains and unwanted programs.

Licensee        : Avira AntiVir Personal - FREE Antivirus
Serial number   : 0000149996-ADJIE-0000001
Platform        : Windows Vista
Windows version : (Service Pack 1)  [6.0.6001]
Boot mode       : Normally booted
Username        : SYSTEM
Computer name   : NICKSPC

Version information:
BUILD.DAT       : 9.0.0.394     17962 Bytes   4/17/2009 11:20:00
AVSCAN.EXE      : 9.0.3.5      466689 Bytes   4/17/2009 16:57:30
AVSCAN.DLL      : 9.0.3.0       40705 Bytes   2/27/2009 18:58:24
LUKE.DLL        : 9.0.3.2      209665 Bytes   2/20/2009 19:35:49
LUKERES.DLL     : 9.0.2.0       12033 Bytes   2/27/2009 18:58:52
ANTIVIR0.VDF    : 7.1.0.0    15603712 Bytes  10/27/2008 20:30:36
ANTIVIR1.VDF    : 7.1.2.12    3336192 Bytes   2/11/2009 04:33:26
ANTIVIR2.VDF    : 7.1.3.185   2010112 Bytes   5/12/2009 19:54:02
ANTIVIR3.VDF    : 7.1.3.231    325632 Bytes   5/19/2009 19:54:03
Engineversion   : 8.2.0.168
AEVDF.DLL       : 8.1.1.1      106868 Bytes   5/19/2009 19:54:09
AESCRIPT.DLL    : 8.1.2.0      389497 Bytes   5/19/2009 19:54:09
AESCN.DLL       : 8.1.2.3      127347 Bytes   5/19/2009 19:54:08
AERDL.DLL       : 8.1.1.3      438645 Bytes  10/30/2008 02:24:41
AEPACK.DLL      : 8.1.3.16     397686 Bytes   5/19/2009 19:54:08
AEOFFICE.DLL    : 8.1.0.36     196987 Bytes   2/27/2009 04:01:56
AEHEUR.DLL      : 8.1.0.129   1761655 Bytes   5/19/2009 19:54:06
AEHELP.DLL      : 8.1.2.2      119158 Bytes   2/27/2009 04:01:56
AEGEN.DLL       : 8.1.1.44     348532 Bytes   5/19/2009 19:54:04
AEEMU.DLL       : 8.1.0.9      393588 Bytes   10/9/2008 22:32:40
AECORE.DLL      : 8.1.6.9      176500 Bytes   5/19/2009 19:54:04
AEBB.DLL        : 8.1.0.3       53618 Bytes   10/9/2008 22:32:40
AVWINLL.DLL     : 9.0.0.3       18177 Bytes  12/12/2008 16:47:59
AVPREF.DLL      : 9.0.0.1       43777 Bytes   12/5/2008 18:32:15
AVREP.DLL       : 8.0.0.3      155905 Bytes   1/20/2009 22:34:28
AVREG.DLL       : 9.0.0.0       36609 Bytes   12/5/2008 18:32:09
AVARKT.DLL      : 9.0.0.3      292609 Bytes   3/24/2009 23:05:41
AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes   1/30/2009 18:37:08
SQLITE3.DLL     : 3.6.1.0      326401 Bytes   1/28/2009 23:03:49
SMTPLIB.DLL     : 9.2.0.25      28417 Bytes    2/2/2009 16:21:33
NETNT.DLL       : 9.0.0.0       11521 Bytes   12/5/2008 18:32:10
RCIMAGE.DLL     : 9.0.0.21    2438401 Bytes    2/9/2009 19:45:45
RCTEXT.DLL      : 9.0.37.0      86785 Bytes   4/17/2009 18:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +SPR,

Start of the scan: Tuesday, May 19, 2009  12:54

Starting search for hidden objects.
'83053' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'chrome.exe' - '1' Module(s) have been scanned
Scan process 'chrome.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
Scan process 'TrustedInstaller.exe' - '1' Module(s) have been scanned
Scan process 'msiexec.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'XAudio.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'stacsv.exe' - '1' Module(s) have been scanned
Scan process 'RoxWatch9.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'QuickDCF2.exe' - '1' Module(s) have been scanned
Scan process 'DLG.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'sttray.exe' - '1' Module(s) have been scanned
Scan process 'AirNCFG.exe' - '1' Module(s) have been scanned
Scan process 'WZCSLDR2.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
63 processes with 63 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
    [INFO]      No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
    [INFO]      No virus was found!
Boot sector 'D:\'
    [INFO]      No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '45' files ).


Starting the file scan:

Begin scan in 'C:\' <OS>
C:\pagefile.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\Windows\SoftwareDistribution\Download\20c1913e70153e1c0685bdb6b0660a1b\BITCA13.tmp
 
  • Archive type: CAB (Microsoft)

    --> 0
      [WARNING]   No further files can be extracted from this archive. The archive will be closed
    [WARNING]   No further files can be extracted from this archive. The archive will be closed
Begin scan in 'D:\' <RECOVERY>


End of the scan: Tuesday, May 19, 2009  13:37
Used time: 43:07 Minute(s)

The scan has been done completely.

  19268 Scanned directories
 268090 Files were scanned
      0 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      1 Files cannot be scanned
 268089 Files not concerned
   1082 Archives were scanned
      3 Warnings
      1 Notes
  83053 Objects were scanned with rootkit scan
      0 Hidden objects were found


and a hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:41 PM, on 5/19/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Nick\Desktop\removal\HiJackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [D-Link D-Link RangeBooster N DWA-140] C:\Program Files\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nick\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7121 bytes
« Last Edit: May 19, 2009, 03:52:06 PM by firefly »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Possible Keyloggers
« Reply #23 on: May 19, 2009, 04:19:58 PM »
43 minutes to scan the whole drive, that's not bad
I see everything looks good

Take advantage of Avira's Scheduler under Administration
The Updates by default should be at 24 hours, I would leave that set and enabled, or Edit the job and have it check Daily updates at a certain time every day, up to you
But you may want to set a Weekly interval Scan of the system, you can even have Avira shut down the system when the scan is complete, you'll see that option after setting up the schedule
I like to set the scan at a time I won't be using the computer, I usually do it on my way out the door going to work
So for me, I set the scheduled scan at 07:15 every Tuesday
That's just an eg..

Don't forget to activate the scheduled scan under the main window in Scheduler, if you need more precise instructions to set the  scheduler, let me know, I'll walk you thru it

Edit>>I forgot about OTListIt2
Can you right click on it and "Run as Admin"
Click on the CLEANUP button
Yes at the prompt to RebootNow, as we are only clearing OTListIt2 from your system
You can choose NO to reboot later, it's up to you
this will also delete OTListIt2.exe from desktop on reboot
« Last Edit: May 19, 2009, 04:22:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline firefly

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Possible Keyloggers
« Reply #24 on: May 19, 2009, 04:51:18 PM »
Hehe, It felt longer than that because the first update took a bit of time too.  Thanks a lot for your help, it's nice to know that I didn't have anything too serious infecting my computers.. unfortunately that means my game info was probably found by some other method besides keyloggers eh?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Possible Keyloggers
« Reply #25 on: May 19, 2009, 05:11:31 PM »
On the XP machine, ComboFix and Malwarebytes did find some malware
On both machines, ensure to keep Java, Flash, Adobe Reader if installed up to date

XP machine is behind on updates, but I think you were installing those
Did it update you to Internet Explorer 7 or 8 yet?

Is your AntiVirus up to date on the XP machine? Do you regularly run a scan?
« Last Edit: May 19, 2009, 05:12:17 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline firefly

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Possible Keyloggers
« Reply #26 on: May 19, 2009, 05:18:25 PM »
Right, I was just expecting to find more than we did.  I think I'm just about done updating the XP, and will update explorer right now, hadn't done that yet.

My antivirus had expired a while ago so it's not getting new updates, but I was still running scans. I think I might switch to this Avira program instead of using an outdated Norton.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Possible Keyloggers
« Reply #27 on: May 19, 2009, 05:23:50 PM »
again, dangerous to have No AntiVirus or an outdated AV
Some things that ComboFix found on the XP machine related to Information stealer
That was probably the culprit to your hacked Wow account or other gaming account

Let me know when your done with Windows Updates
Then we should remove Norton's properly and install Avira
Give me a nod when your ready to do that step

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline firefly

  • Newbie
  • *
  • Posts: 15
  • Karma: +0/-0
    • View Profile
Possible Keyloggers
« Reply #28 on: May 30, 2009, 07:13:54 PM »
Hey, sorry for the delay.  I was out of town.  Anyway, I think I finally caught up my computer (the XP) on updates so I'm ready to switch out Norton for Avira if you've got a minute to walk me through that.